npm

hyperliquid-composer @1.0.0

Vulnerability report · Last retrieved from osv.dev August 31, 2026 at 11:43 PM UTC

Malicious

OSV ID

MAL-2026-15627

Ecosystem

npm

Summary

bin/cli.js (also declared as the package main) collects the installer's username via whoami / os.userInfo() , plus os.hostname() and platform, and POSTs them to the hardcoded Cloudflare Workers endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The exfiltration fires on require() of the module or on CLI invocation, with no user consent or configuration. The package name resembles legitimate Hyperliquid tooling.

Source: amazon-inspector (1fb2b7d17a47aa4fcd585374f33063197f52d6ba8619e4105ae5a1d30331bb62)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.